CVE-2026-58575
8.8Dell · PowerStore
Dell PowerStore systems are vulnerable to an authentication bypass via spoofing, allowing an authenticated user to escalate privileges to administrative levels.
Executive summary
A high-severity authentication bypass vulnerability in Dell PowerStore allows authenticated users to escalate privileges to Administrator, potentially leading to full system compromise.
Vulnerability
The system is susceptible to an authentication bypass by spoofing (CWE-290), which allows an attacker who already possesses low-level user credentials to bypass security controls and gain administrative access.
Business impact
This vulnerability carries a CVSS score of 8.8, indicating a high risk to the confidentiality, integrity, and availability of stored data. An attacker who successfully escalates privileges to Administrator gains complete control over the storage array, enabling unauthorized data access, modification, or total system disruption, which could lead to significant operational downtime and regulatory non-compliance.
Remediation
Immediate Action: Update all affected Dell PowerStore appliances to version 4.1.0.6-2771237 or later as specified in the vendor security advisory.
Proactive Monitoring: Audit administrative access logs for unusual login patterns or privilege escalation attempts that deviate from established user behavior baselines.
Compensating Controls: Restrict access to the PowerStore management interface to trusted administrative networks and implement multi-factor authentication where possible to mitigate the impact of compromised low-privileged accounts.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
The ability for an authenticated user to achieve full administrative control represents a significant security failure within the PowerStore management stack. Administrators should prioritize this update within their standard maintenance window to eliminate the risk of privilege escalation. Failure to patch these systems leaves the storage infrastructure vulnerable to internal threats or compromised user accounts.